open-webui/backend/open_webui/routers
Classic298 746caa7c78
fix: honor ENABLE_PROFILE_IMAGE_URL_FORWARDING for channel webhook profile images (#29889)
Setting ENABLE_PROFILE_IMAGE_URL_FORWARDING=false stops the user and model profile image endpoints from redirecting browsers to external avatar URLs, but channel webhook avatars kept redirecting regardless. An operator who turned the setting off precisely to stop clients leaking their IP, User-Agent and Referer to outside origins still leaked all three whenever anyone viewed a channel message posted by a webhook with an external profile image URL.

The webhook profile image endpoint now reads the same setting the user and model endpoints already read, and serves the bundled default image instead of the redirect when forwarding is off. Stored URLs are untouched, so turning the setting back on restores the previous behaviour.

Verified against the real handler with seeded webhook rows: with the setting unset or true the endpoint still returns the 302 with the original Location, with it false it returns the default favicon as image/png with no Location and no header carrying the external host, and the data URI, no image and unknown webhook responses are byte identical in both states.
2026-09-12 16:06:34 -05:00
..
analytics.py refac 2026-06-29 01:38:41 -05:00
audio.py refac 2026-09-06 16:48:30 -04:00
auths.py refac 2026-09-06 17:10:01 -04:00
automations.py refac 2026-08-13 17:26:38 -06:00
calendar.py refac 2026-06-29 13:03:14 -05:00
channels.py fix: honor ENABLE_PROFILE_IMAGE_URL_FORWARDING for channel webhook profile images (#29889) 2026-09-12 16:06:34 -05:00
chats.py refac 2026-08-25 13:18:38 -04:00
configs.py refac 2026-09-07 12:15:20 -04:00
evaluations.py refac 2026-09-06 16:48:30 -04:00
files.py fix: don't hold a database connection for the lifetime of an SSE stream (#28183) 2026-08-17 01:46:54 -06:00
folders.py fix: keep folder parent references acyclic (#28748) 2026-08-24 17:06:19 -04:00
functions.py refac 2026-08-17 01:21:58 -07:00
groups.py refac 2026-06-29 05:47:21 -05:00
images.py refac 2026-09-12 17:02:44 -04:00
knowledge.py refac 2026-09-09 17:09:53 -04:00
memories.py refac 2026-08-11 17:35:05 -06:00
models.py refac 2026-09-09 17:09:45 -04:00
notes.py refac 2026-08-25 13:18:38 -04:00
notifications.py refac 2026-07-27 19:39:36 -04:00
ollama.py fix: stop forwarding upstream Server and Date headers from the OpenAI and Ollama proxies (#29843) 2026-09-09 16:35:48 -04:00
openai.py fix: stop forwarding upstream Server and Date headers from the OpenAI and Ollama proxies (#29843) 2026-09-09 16:35:48 -04:00
pipelines.py perf: skip pipeline filter session setup when no filters exist (#29146) 2026-08-28 12:22:23 -04:00
prompts.py refac 2026-08-31 00:39:16 -04:00
retrieval.py fix: only log a reranking model change when the request carries one (#29922) 2026-09-12 16:04:14 -05:00
scim.py refac 2026-08-23 13:49:50 -04:00
skills.py perf: stop scanning every skill on each listing and chat turn (#28798) 2026-08-19 11:07:33 -07:00
tasks.py refac 2026-08-11 01:15:05 -06:00
terminals.py fix: stop forwarding upstream Server and Date headers from the terminal proxy (#29841) 2026-09-09 12:31:02 -04:00
tools.py refactor: scope tool export to tools the caller can write (#29310) 2026-09-06 17:44:45 -04:00
users.py refac 2026-09-07 14:46:52 -04:00
utils.py refac 2026-09-06 17:27:30 -04:00